CVE-2021-25281 is a critical authentication bypass vulnerability affecting SaltStack Salt versions prior to 3002.5, specifically impacting the salt-api component. This flaw allows an unauthenticated attacker to remotely execute arbitrary wheel modules on the Salt master, affecting various Debian, Fedora, and SaltStack Salt deployments. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). While not listed on CISA's KEV catalog, public exploit modules exist for Metasploit and Nuclei, indicating readily available exploit code, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2015.8.10CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2015.8.11, < 2015.8.13CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.0, < 2016.3.4CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.5, < 2016.3.6CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* | ||
>= 2016.3.7, < 2016.3.8CPE matchmatch criteria | cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.